Senior Director, Cybersecurity & Enterprise Infrastructure
Rimkus
Job Description
Job Description:\n\nJoin Rimkus and unlock your potential with endless opportunities for growth, learning, and making a difference!\nRimkus is a worldwide leader in Engineering and Technical Consulting. Rimkus experts specialize in building envelope, engineering, forensic consulting, dispute resolution, construction management services, and solutions built for the environment.\nNOW IS THE TIME to join this growing and stable company!\n\nPosition Summary\n\nThe Senior Director, Cybersecurity & Enterprise Infrastructure is the accountable leader for the security, resilience, and technical foundation of Rimkus's technology estate. Reporting to the Chief Transformation Officer, this leader owns enterprise cybersecurity, cloud and hybrid infrastructure, endpoint and identity platforms, the enterprise data platform, the technology integration of acquired businesses, and the compliance and audit program that evidences all of it.\nThis is a leader-of-leaders role. It directs a multidisciplinary organization of infrastructure engineers, data engineers, systems and security staff, and the IT systems director function — setting architecture and standards, building bench strength, and converting security findings into completed, evidenced remediation.\nRimkus operates in a client environment where confidentiality, privileged information, and defensible data handling are core to the business. As a private-equity-backed, acquisitive professional services firm, the company is subject to sponsor-directed security assessments, client due diligence, and formal audit expectations — while simultaneously acquiring and integrating businesses on a recurring basis. Cybersecurity is therefore not a subordinate function of this role — it is its center of gravity, and every acquisition either strengthens or dilutes it.\nBecause the position reports into the Transformation organization, it carries an explicit mandate to standardize, consolidate, and modernize rather than merely operate.\nScope & Organizational Context\n\n• Security ownership: This role is the company's accountable cybersecurity leader — including security strategy, security operations, incident response, and the formal compliance and audit program. It also owns the technology compliance control library and evidence readiness.\n• Technical breadth: Microsoft Entra ID and M365 E5 identity estate, Azure and hybrid infrastructure, network and remote access, endpoint and device management, backup/DR, the enterprise data and analytics platform, and enterprise applications infrastructure.\n• Organizational mandate: Rebuild depth and continuity following the departure of long-tenured technical staff. A significant portion of the first year is eliminating key-person dependency through documentation, cross-training, hiring, and automation — so that no critical system depends on a single individual's undocumented knowledge.\n• Transformation mandate: Reporting into the Transformation organization, this role is expected to consolidate and standardize a technology estate that has grown through acquisition — retiring redundant platforms, unifying identity and endpoint management, and establishing a repeatable integration playbook rather than treating each deal as a one-off project.\n• Inorganic growth: Rimkus grows through acquisition. This role owns the technology and security workstream across the full deal lifecycle — pre-LOI and confirmatory diligence, Day 1 readiness, post-close integration, and platform rationalization — and is accountable for ensuring acquired environments are brought up to Rimkus control standards on a defined timeline.\n• Stakeholders: Executive leadership, the Transformation organization, Corporate Development, the private-equity sponsor's technology operating team, Legal and Risk, Compliance, Finance, HR, business-line and acquired-entity leadership, clients responding to security due diligence, and external assessment, audit, and managed-service partners.\nKey Responsibilities\nCybersecurity Strategy & Leadership\n• Own enterprise cybersecurity strategy, target-state architecture, and a funded multi-year roadmap aligned to business risk and growth.\n• Serve as the accountable security leader: maintain the security policy set, the enterprise risk register with quantified business impact, and documented risk-acceptance decisions.\n• Establish and chair a security governance forum; report posture, risk trend, and remediation progress to executive leadership, the Board, and the private-equity sponsor on a defined cadence.\n• Lead and coordinate independent security assessments, penetration tests, and sponsor-directed reviews; own the remediation plan, evidence package, and measurable score improvement window over window.\n• Own client-facing security due diligence, security questionnaires, contractual security terms, and cyber insurance underwriting responses.\n• Build and operate a security awareness, phishing simulation, and role-based training program with measured behavioral outcomes.\n• Set the security investment strategy: extract full value from entitlements already licensed before adding tooling; justify new spend with quantified risk reduction.Identity & Access Management\nIdentity is the primary security perimeter for this environment. This is the single most consequential technical accountability in the role.\n• Own Microsoft Entra ID architecture, hybrid identity, and the M365 tenant identity security model end to end.\n• Design, govern, and change-control Conditional Access. Replace accumulated app-by-app policy sprawl with a documented, tenant-wide baseline (all users × all cloud applications) plus a governed exception register with owners and expiry dates.\n• Drive universal multifactor authentication to full coverage and lead adoption of phishing-resistant methods (FIDO2/passkeys, Windows Hello for Business, certificate-based authentication); retire weak factors.\n• Eliminate legacy authentication protocols enterprise-wide and migrate remaining dependencies — scanners, SMTP relays, line-of-business integrations — to OAuth 2.0 and modern authentication.\n• Implement and operate Privileged Identity Management: just-in-time elevation, approval workflow, time-bound roles, session justification, and recurring access reviews. Eliminate standing administrative privilege.\n• Govern trusted network locations and remote-access trust assumptions. Ensure privileged and administrative access paths — management APIs, PowerShell, device-code flow, service-to-service — are explicitly controlled rather than implicitly trusted by network position.\n• Own service principal, enterprise application, and OAuth consent governance: least-privilege API permissions, admin-consent workflow, ownership attestation, and credential/secret rotation.\n• Establish identity lifecycle automation (joiner / mover / leaver), entitlement and access reviews, guest and external-collaboration governance, and the elimination of shared and generic accounts.\n• Harden credential standards: minimum length, breach-password correlation, rotation policy, elimination of blanket expiry exemptions, and group-managed service accounts for service identities.Security Operations, Threat Detection & Incident Response\n• Own SIEM and security analytics (Microsoft Sentinel): data-source onboarding and completeness, retention and archive tiering sufficient for forensic reconstruction, detection engineering, tuning, and ingestion cost management.\n• Validate detection coverage against MITRE ATT&CK and close gaps across initial access, credential access, persistence, privilege escalation, lateral movement, and exfiltration.\n• Own the Microsoft Defender XDR stack — Defender for Identity, Endpoint, Cloud Apps/CASB, and Office 365 — with defined triage SLAs by severity and a managed, non-aging alert queue.\n• Establish continuous (24×7) monitoring coverage, in-house or through a managed detection and response partner, with defined escalation paths, on-call rotation, and enforced performance SLAs.\n• Author, socialize, and test the incident response plan and playbooks — credential exposure, business email compromise, ransomware, insider data theft, service-account and privileged-identity compromise, third-party breach — with named roles and decision authority.\n• Run tabletop and purple-team exercises at least annually; drive after-action findings to closure.\n• Lead investigation and containment during live incidents: forensic triage, evidence preservation and chain of custody, and coordination with Legal, HR, Communications, outside counsel, insurers, and law enforcement as required.\n• Own identity threat detection and response — including credential-exposure response, risky-identity remediation to documented closure within SLA, service-account credential attack detection, and token-theft defense.\n• Own vulnerability and patch management, external attack surface monitoring, secure configuration baselines, and remediation SLAs by severity.\n• Own the insider risk and data loss prevention program: data classification, sensitivity labeling, and monitoring and enforcement against removable-media exfiltration, mass download, and sharing to personal accounts — with specific controls for PHI, PCI, PII, and litigation-sensitive material.Cloud & Enterprise Infrastructure\n• Direct Azure and hybrid cloud strategy: landing zone and subscription governance, network topology, identity and RBAC model, Key Vault and secrets management, Azure Policy, Defender for Cloud, and Well-Architected reviews.\n• Own infrastructure-as-code and configuration management; move change execution from manual console work to automated, peer-reviewed, auditable pipelines.\n• Oversee network, firewall, SD-WAN, DNS and email security, and remote access across all offices; modernize implicitly trusted VPN architecture toward zero-trust network access and segmentation.\n• Own data center, virtualization, storage, and the remaining on-premises footprint, including cloud migration and legacy platform exit plans.\n• Own backup, immutable and air-gapped recovery, disaster recovery, and business continuity; define, test, and evidence RTO and RPO for every critical system with documented exercises at least annually.\n• Own the Microsoft 365 estate — Exchange Online, SharePoint/OneDrive, Teams — and Copilot/AI readiness including the data-governance prerequisites.\n• Own ITSM discipline: change, incident, and problem management, capacity planning, availability and service-delivery SLAs, and published operational metrics.Endpoint, Device Trust & Modern Workplace\n• Own endpoint management (Intune, Autopilot, and co-managed configuration manager estate); consolidate legacy management paths and retire duplicate tooling.\n• Raise device compliance above target and extend compliant-device Conditional Access from selected applications to all users and all workloads.\n• Enforce full-disk encryption, EDR coverage, application control, and patch compliance to defined, reported thresholds across Windows, macOS, iOS, and Android.\n• Own the end-user computing experience, service desk performance, and the quality of onboarding and offboarding execution.Data Engineering & Analytics Platform\n• Lead the data engineering function: pipeline and integration architecture, orchestration, warehouse/lakehouse platform, and business intelligence delivery.\n• Establish data governance — ownership, classification, lineage, retention, and quality standards — in partnership with Legal, Compliance, and business lines.\n• Secure the data platform: least-privilege and row/column-level access, managed identities and secrets management, encryption in transit and at rest, and monitoring of analytics service accounts and service principals.\n• Partner with business leadership to deliver reporting and analytics products that improve client delivery, utilization, and operational decision-making.\n• Govern AI and machine learning adoption, including acceptable-use standards, data-protection controls, and review of AI-connected data surfaces.Compliance, Audit & Risk Governance\n• Own the technology compliance program mapped to NIST Cybersecurity Framework and NIST 800-53, CIS Controls v8, ISO 27001, and applicable HIPAA, PCI DSS, and privacy obligations.\n• Maintain the control library, control owners, testing calendar, and evidence repository; operate continuous control monitoring so the organization is audit-ready at any time rather than at audit time.\n• Lead internal and external audits and assessments, SOC 2 readiness where applicable, and client and legal security due diligence.\n• Ensure audit and activity log retention, completeness, and immutability are sufficient for forensic reconstruction, legal hold, and eDiscovery obligations; own the Purview compliance capability.\n• Own third-party and vendor risk assessment, security terms in contracts, and ongoing supplier monitoring.\n• Ensure records retention, data residency, and cross-border data handling meet client, contractual, and regulatory requirements across the international footprint.\n• Extend the compliance and control program to acquired entities on a defined timeline, and represent the combined environment in client, sponsor, and audit inquiries.Mergers, Acquisitions & Technology Integration\nRimkus grows inorganically. This role owns the technology and security workstream across the full deal lifecycle and is expected to make integration a repeatable capability rather than a recurring fire drill.\n• Diligence: Lead technology and cybersecurity due diligence on acquisition targets — identity and tenant architecture, security posture and control maturity, prior incidents and breach history, infrastructure and technical debt, application and data estate, licensing and contract assignability, key-person and vendor dependencies, and cyber insurance history.\n• Risk quantification: Translate diligence findings into quantified integration cost, one-time and run-rate synergy estimates, remediation timelines, and identified deal risks — presented in a form Corporate Development, the Transformation organization, and the sponsor can act on. Escalate findings material to valuation or deal structure.\n• Day 1 readiness: Own Day 1 technology readiness — email and collaboration access, network connectivity, endpoint and EDR coverage, credential issuance, and a minimum security baseline for acquired users before broad access is granted. No acquired environment gains trusted access to Rimkus systems before defined controls are verified.\n• Integration execution: Direct post-close integration: Entra tenant and domain consolidation, identity and mailbox migration, device enrollment and endpoint management onboarding, network integration and segmentation, application rationalization, and data migration with classification and retention applied.\n• Control uplift: Bring acquired environments to Rimkus security standards on a committed timeline — MFA and Conditional Access enforcement, privileged access remediation,
- Senior IT Manager, Enterprise Infrastructure & Operations Houston, TX (Primary Location) Travel: Up to 20%About... ...transformation initiatives, cloud adoption, cybersecurity programs, operational technology... ...discretion of the CSWI Board of Directors.Benefits: At RectorSeal, our...SeniorFull timeFor contractors
$163.4k - $322.1k
...challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help... ...12/31/2026. Work you'll do As a Cloud Security Senior Manager, Azure Infrastructure & AI on the Enterprise Security team, you will be responsible for… Leading...SeniorWork at officeLocal areaVisa sponsorship$105.4k - $207.8k
...opportunities businesses face in cybersecurity. Join our team to deliver... .../2026. Work you'll do As a Senior Consultant, Strategy,... ...platform as a service security, infrastructure security, artificial... ...guidance to others The team Our Enterprise Security offering embeds...SeniorLocal areaVisa sponsorship- ...AI-first approach, the Senior Manager - Real Estate Technology Infrastructure will be a bridge... ...reports to the Managing Director, Real Estate Technology... ...Sourcing to negotiate enterprise-wide agreements that leverage... ...building networks, cybersecurity, and integrated...SeniorContract workFor contractorsCasual workWork at officeLocal areaRemote work3 days per week
- ...Senior Executive Business Partner, Chief Executive Officer (CEO)'s Office About the Company Industry... ...Data Security Regulatory Affairs Cybersecurity Software Development Computing Infrastructure Data & Analytics Hosting Services Information...SeniorWork at office
- ...Position Overview Client is seeking a Senior Hybrid Infrastructure Engineer to design, implement, operate, and modernize enterprise infrastructure across on-premises and... ...engineering, cloud architecture, automation, cybersecurity, and operational excellence to deliver...SeniorTemporary work
- ...Senior IT Infrastructure EngineerThe Senior IT Infrastructure Engineer is responsible for the design... ..., scalability, performance, and cybersecurity across all infrastructure systems.The... ...to:Design, implement, and maintain enterprise infrastructure across on-premises and...SeniorMonday to Friday
- ...building era-defining space infrastructure and delivering technology-... ...seeking a bold and dynamic Senior Infrastructure Systems Administrator... ..., and cost governance. Own enterprise storage and backup systems;... .... Partner with the cybersecurity and Ground Systems teams to...SeniorFor contractorsWork at officeWeekend workAfternoon shift
- ...expertise will shape the future of enterprise data capabilities in financial services. As Senior Principal Solutions Architect... ...engineering, operations, and infrastructure teams to ensure architectural... ...with Legal, Privacy, Cybersecurity, and Risk teams to embed governance...SeniorFull timeWork experience placementWork at officeFlexible hours
- Senior Principal Presales Systems Engineer, Cloud and AI NetworkingThis... ...Who We Are:Hewlett Packard Enterprise is the global edge-to-cloud... ...such as Multi-Cloud, Cybersecurity, Automation, IoT, AI,... ...design for AI/ML Networking Infrastructure, Data Center, and WAN networking...SeniorFull timeWork experience placementLocal areaImmediate startRemote workWork from home
- ...located in the Houston or Dallas-Fort Worth Area.As a Regional Director (RD) at Optiv, you'll lead your team's development to sell... ...Fortune 1000 accounts.Experience in and knowledge of the IT infrastructure, Risk and Compliance markets and competitors.Experience selling...Full timeLocal areaRemote workWork from home
- ...Job Description Job Description Senior Infrastructure Analyst – L3 - Projects Location: Houston Department: Professional Services... ...Uprite is a trusted technology partner, providing managed IT, cybersecurity, cloud, and phone solutions to growing businesses across...SeniorRemote workNight shift
- We are seeking a Senior Network Engineer to lead the design,... ...implementation, and support of complex enterprise network environments. This... ...background in enterprise infrastructure, cloud networking, network... ...infrastructure, cloud, cybersecurity, and application teams to...Senior
$55 - $60 per hour
DescriptionKforce has a client that is seeking a Senior OT Cybersecurity Risk Analyst in Houston, TX.Summary:In this role, you will partner closely with the business, infrastructure, and OT teams to understand how systems are used in the real world and how cybersecurity...Senior- Spencer Ogden is seeking a Senior Vice President to lead sourcing, evaluating, and executing investments in energy infrastructure and LNG sectors. The role involves portfolio management and interaction with senior leadership and external partners. You will mentor junior...Senior
- ...we are expanding and looking to grow our team with a new IT Infrastructure Engineer! Position Summary: Working on the Operations... ...Experience in Infrastructure and Operations services Experience in Enterprise Cloud Migration and Transformation Intermediate knowledge...SeniorWork at officeRemote work
- ...9144675Reference26-23968 In this role, you will partner closely with the business, infrastructure, and OT teams to understand how systems are used in the real world and how cybersecurity can best support reliability, security, and business outcomes. You will help translate...Senior
$165k - $242k
The Senior Manager, IT Sales Operations is responsible for the strategy, governance,... ...investments, governance standards, and enterprise business objectives.The expected annual... ...Ensure platform stability, supportability, cybersecurity compliance, data governance, policy...SeniorFor contractorsLocal area- Jobot is seeking an experienced Senior Cybersecurity Analyst to join a collaborative enterprise security team protecting critical business systems, applications... ...the organization while partnering with IT, infrastructure, and application teams to strengthen security posture...Senior
- Haskell seeks a Project Director to lead major water infrastructure programs from pursuit to closeout. You will own the project, build a strong team, drive preconstruction, manage client relationships, and deliver results on $50M-$300M+ programs. You’ll partner with municipalities...Senior
$145k - $165k
...Job Description Job Description Title: Senior. Systems Engineer - Infrastructure & Cloud Location: Houston, TX Salary: $145,000 - $165,00... ...implementation, administration, optimization, and support of enterprise infrastructure with a primary focus on Linux operating...SeniorLocal area- Aroha Technologies, Inc. in Houston, TX is seeking a Senior OT Cybersecurity Risk Analyst for a 12-month contract onsite. You will partner with business, engineering, infrastructure, and OT teams to identify, assess, and communicate cybersecurity risks across OT/ICS environments...SeniorContract work
- Hatch Ltd. is looking for Intermediate and Senior Commissioning Managers in Houston, TX, specializing in metals, mining, or infrastructure. The role involves leading the planning and execution of commissioning projects with a strong emphasis on safety, quality, and compliance...Senior
- Connect Search, LLC is seeking a Senior Investment Analyst to join a growing finance team focused on evaluating and financing large-scale energy infrastructure investments. You will build and maintain sophisticated project finance models, support budgeting and strategic...Senior
- GHD in Houston is seeking an experienced Project Manager to lead complex water and wastewater infrastructure programs from planning through construction. You will manage multidisciplinary teams, maintain client relationships, and ensure projects stay on time and within...Senior
- Giga Energy in Houston is seeking a Senior Accountant to join our Controllership team. You’ll own key general ledger areas, drive a... ...performing group working at a pace aligned with our growing AI infrastructure business. This role emphasizes building financial...Senior
- Enbridge in Houston, TX, seeks a Senior Advisor, Project Development to provide senior-level project management across planning, procurement, construction, and startup phases of critical infrastructure. You will mentor teams, manage scope, schedule, and cost, and ensure...Senior
- Clayton Services in Houston, TX seeks a Senior Solutions Engineer to lead complex infrastructure projects and modernize IT environments for diverse clients. You will drive cloud transformations, design secure hybrid environments, and guide identity and endpoint management...Senior
- Delan Associates, Inc. is seeking a cybersecurity professional to join our team at the intersection of people, technology, and operations... ...outcomes. In this role, you will partner with business, infrastructure, and OT teams to understand real-world usage, support risk-informed...Senior
- A dynamic energy firm in Houston is seeking a Finance Senior Associate to focus on analyzing and financing large-scale energy infrastructure projects. Ideal candidates will have a Bachelor’s in Finance and 3-5 years of experience in project finance modeling. This role...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Cybersecurity & Enterprise Infrastructure. Be the first to apply!
- director of business systems Houston, TX
- business affairs manager Houston, TX
- food business manager Houston, TX
- business director Houston, TX
- manager business intelligence Houston, TX
- director of enterprise application services Houston, TX
- manager enterprise sales Houston, TX
- director business planning Houston, TX
- business opportunity manager Houston, TX
- director business analysis Houston, TX



